Topic · 6 articles

Tips & Tricks.

Curated tips on AI-assisted fuzzing, Kubernetes hardening, agentic SOC workflows, and API security — practical field notes from real infrastructure.

GitHub Actions OIDC to AWS: Drop Static Keys for Good

Wire GitHub Actions OIDC to AWS correctly: scope the sub claim, handle the July 15 immutable-claim change, and avoid the trust policy traps tutorials skip.

Read more

Agentic SOC in 2026: 10 Tips for Safe Triage

Battle-tested agentic SOC tips: gate autonomy on 90% shadow-mode concordance, split verdict from action, and treat every log line as attacker-authored.

Read more

Run AI Fuzzing on Your Own Repo Before Attackers Do

OSS-Fuzz-Gen, Buttercup, and Atheris run on a laptop with one LLM key. Ten practical commands to fuzz your own repo before attackers do.

Read more

OWASP API Top 10: Shadow APIs and BOLA Tips for 2026

Battle-tested OWASP API Security Top 10 tips for 2026: hunt shadow and zombie APIs at runtime, test BOLA in CI, and close the gaps that breached Optus.

Read more

Prompt Injection Defense: 10 Tips That Hold Up

Why LLM agent guardrails fail under adaptive attack, and the architectural patterns that actually contain prompt injection in 2026.

Read more

Non-Human Identity Governance: Field Tips for 2026

How to discover, scope, and govern service accounts, API keys, tokens, and AI agents before machine credentials become your breach path.

Read more

Browse other topics

All writing

Subscribe to the Technical Journal

Deep dives into infrastructure, security, and technical leadership. No noise, just engineering rigor. Subscribe and grab the 2026 AI-agent & infrastructure security checklist.